Effective September 21, 2026. This replaces the policy last updated May 15, 2021.
SERVER SIDEKICK LLC ("we", "us") makes the Server Sidekick app (the "app") and runs https://www.serversidekick.app (the "website").
Server Sidekick 2.0 does not collect your data. The app has no accounts, no ads, no analytics, no crash reporting and no in-app purchases, and we run no server that the app talks to. Nothing you enter into it is sent to us.
Your servers, credentials and keys stay on your device.
The app connects only to the servers and services you set up in it. It does not contact us, or anyone else, on its own.
We do not sell or share personal information, and we do not use it for advertising or profiling.
The sections below give the detail. If you used a version before 2.0, read "Earlier versions" as well.
Everything you put into the app is stored on your device only: saved hosts and groups, usernames, passwords, SSH keys, the commands you run, a log of the app's activity, metrics it has sampled from your servers, alert rules, favorites and settings.
Passwords and SSH keys are stored encrypted. The encryption key is held in your device's secure storage (the Keychain on Apple platforms, the Keystore on Android). The rest is kept in the app's private storage, which your device's operating system keeps other apps out of.
If you turn on app lock, the app asks your device to verify you with Face ID, Touch ID, your fingerprint or your passcode. Your device does the check. The app learns only whether it passed and never receives your biometric data.
Deleting the app deletes its data. We cannot recover it for you, because we never had it.
The app connects only where you tell it to:
Your servers, over SSH and SFTP. The commands you run and the files you transfer go between your device and those servers, not through us. SSH encrypts that traffic.
Services on your own network or accounts, such as a Proxmox host or a Kubernetes cluster you have added.
Your local network, when you ask the app to scan it for SSH servers. The results stay on your device. On iOS this is why the app asks for Local Network access.
Links you tap, such as the website or a help page, which open in your browser. Those sites have their own privacy policies.
The servers and services you connect to are run by you or by third parties. We have no access to what they collect, and their own policies apply.
The app only sends something out when you ask it to:
Backups. You can export your hosts, groups and credentials (including SSH keys) to an encrypted file protected by a passphrase you choose. The passphrase never leaves your device, and we cannot recover a backup if you lose it. You decide where the file goes. If you save it to iCloud Drive, Google Drive or similar, that service's policy applies to it.
Sending credentials. You can put the credentials you select into a file encrypted with a passphrase you choose, and hand it to your device's share sheet. It goes wherever you choose there. The Share button in Settings shares only a link to the app.
Files. When you upload a file to a server, the app reads only the files you pick with the system file picker or photo library.
Contacting support. "Email support" opens a message to support@serversidekick.app in your own mail app. If you send it, we receive your email address and whatever you write or attach, and we use it to answer you and to improve the app.
Permission
Why
Internet and network state
To connect to the servers you set up, and to show whether you are online.
Notifications
For the alerts you set up. The app raises them on your device itself; there is no push server.
Face ID, fingerprint
Only for app lock, as above.
Local network (iOS)
Only to scan for SSH servers when you ask.
Photo library (iOS)
Only to upload a photo or file you pick.
The app does not ask for your location, contacts, camera, microphone or advertising ID, and it does not read device identifiers.
The website is hosted on Google Sites. We do not run analytics or advertising on it. Google may process technical information such as your IP address and browser type to deliver and secure the site, under Google's privacy policy at https://policies.google.com/privacy.
Versions of the app before 2.0 worked differently. If you used one, this applies to you:
Accounts. You could sign in with an email address, or with Google or Apple. Sign-in used Google Firebase Authentication, which keeps the email address and basic account details (an account ID, the sign-in method and sign-in dates).
Ads. The app showed ads, served by Google AdMob, unless you had bought the upgrade that removes them. AdMob may collect and use data such as your device's advertising ID and IP address to serve and measure ads. See https://policies.google.com/privacy.
Purchases. Purchases were handled by the Apple App Store or Google Play, and we used RevenueCat to check what you had bought. We never saw your payment card details.
Your servers and credentials stayed on your device in those versions too.
Version 2.0 removes all of this. If you signed in to an earlier version, we may still hold that email address, and RevenueCat may still hold the purchase record. To have them deleted, email us at the address below from that address, or tell us which address it was.
Because version 2.0 sends us nothing, there is normally no data of yours for us to access, correct, delete or hand back. The exceptions are the emails you send to support and the account and purchase records from earlier versions.
For those, you can ask us to tell you what we hold, correct it, delete it, restrict how we use it or give you a copy in a common format. This applies wherever you live, including if you are in the European Economic Area, the United Kingdom or California. We answer within 30 days, and we may ask you to confirm who you are first. You can also complain to your local data protection authority. We do not sell or share personal information as those terms are defined in California law.
Where the law requires a legal basis for the little we hold, it is our legitimate interest in answering your emails and running the app you used, or your consent, or a legal obligation.
We are based in the United States. Any personal data we hold, such as support emails and earlier-version account records, is processed there and by the providers named above.
Your data stays on your device, protected by the platform's own security and the app's encryption. No method of storage or transmission is perfectly secure, and we cannot guarantee it.
The app is not directed at anyone under 18, and we do not knowingly collect personal information from children. If you believe a child has sent us personal information, contact us and we will delete it.
We will post any change on this page and update the date at the top. Changes take effect when posted.
SERVER SIDEKICK LLC
support@serversidekick.app